Live data from Hacker News

Apple alerts users in 92 nations to mercenary spyware attacks

techcrunch.com

171–180 of 301 posts

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#171
post #96

It's probably far worse with Android users that Google is not disclosing. I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.

> I'm seriously considering changing to Apple after this. Ironically that may be worse for you. iMessage is probably a critical step in 60% (or more) of these exploits, and the various unicode/pdf etc rendering engines are responsible in many exploits. Android's open-source nature likely means that a lot of these things are found by security researchers first. Don't forget that zerodium still pays more for an android…

> Plus, the huge variability between Samsung/Google/Moto/Huawei etc makes it triply hard for a single exploit to be successful.

That variability is a double-edged sword. Manufacturer-added Android bundleware is notorious for being shoddily built and could easily represent added points of ingress.

Which is why I wish it were practical to replace OEM Android versions with GrapheneOS/CalyxOS or similar on the latest devices, similar to how a cutting edge PC can run one’s choice of Linux. As long as more secure or at least more standardized Android distributions can only run on devices with some age on them, their popularity will be limited even among the technically inclined.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#172

The message from Apple is so vague that it's useless. It just says to be afraid. There's no advice on what action to take.

The article omitted it, but the message says to update iOS to the latest software and enable its lockdown mode.

Right. That's a "turn it off and turn it on again" tech support answer.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#173
post #9

Earlier quoted context omitted.

Well the they might be just a college student, but they could have a relationship with the actual target in some way. And if it's part of a complex operation they could be trying some indirect approaches.

Or maybe have a bigger blast radius so that it is difficult to know the exact targets. Drown the detection algos in the noise.

Exactly. If you're identifying targets by noisy proxy signals (geo/IP + behavior?) then you're going to have non-zero false positives.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#174

There’s a reddit thread by somebody who got one of these: https://old.reddit.com/r/iphone/comments/1c10jai/i_have_rece... The interesting thing IMO is they claim to just be some random college student. Which seems believable because if they were a real secret squirrel I guess they wouldn’t ask reddit about it, haha. I wonder if the hackers are targeting people based on phone numbers or something. (I could imagine a c…

Everyone's thinking academic secrets but have they engaged in activism in any way shape or form? Being able to take activists and discredit them is an amazing ability. I would not at all be surprised if the xz compression backdoor was an attempt by a certain government to gain the ability to discredit anyone that is against them in anyway.

College students are a traditional target of oppressive or authoritarian regimes. Teaching young adults to view the world through different lenses and systems is an important part of most college programs, as is a significant amount of self-discovery, and both lend themselves very well to activism, especially since young adults are rarely so jaded as to feel like they "can't do anything about it"

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#175

Earlier quoted context omitted.

"random college student" I think there's a misunderstanding on what constitutes a valid or ideal target for state sponsored (or "mercenary") attackers. Simply working at a research lab, industrial manufacturer, power station, tech company or knowing a certain professor can put you on a target list.

Well dang I work in a research lab and I didn’t get an email. I’m just going to assume my research is so interesting that they sent the real badasses after me, somebody that Apple can’t catch. The truth is too ego-shattering.

You probably have been targeted with the more advanced spyware that Apple hasn’t detected yet. ;)

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#176
post #96

It's probably far worse with Android users that Google is not disclosing. I'm seriously considering changing to Apple after this. Not that its secure but that they are willing to go to this length to communicate it.

Reading between the lines, one thing that I expect Apple has but may not be discussing -- root-cause replayability post-infection, across all Apple devices.

I.e. infection is eventually discovered, Apple isolates the vulnerability's entry point, then Apple has some ability to re-scan all devices to detect which may have also had the attack targeted against them

Hashing some data that can serve as a fingerprint makes sense from a herd standpoint (hell, even something as simple as call stack after iMessage received)

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#177

Earlier quoted context omitted.

You'd be surprised. A college student in an interesting field is an interesting target. Doesn't mean he's done anything nefarious or even shady. Industrial espionage is a thing.

Why would a college student be an interesting target simply for being a college student in an interesting field? If they work at an interesting company or something like that I would understand, but the knowledge that is accessible in colleges is not some super secret stuff or am I missing something?

Colleges are basically outsourced green field R&D setup through professors as well as Patent departments to monetize their internal/grant research spend.. Sampling in a large company what you would happen upon is mundane additions to complex solutions you would be unlikely to want to copy if you weren't along for the earlier parts of the ride.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#178

Earlier quoted context omitted.

> I'm seriously considering changing to Apple after this. Ironically that may be worse for you. iMessage is probably a critical step in 60% (or more) of these exploits, and the various unicode/pdf etc rendering engines are responsible in many exploits. Android's open-source nature likely means that a lot of these things are found by security researchers first. Don't forget that zerodium still pays more for an android…

I do not believe the android Messages application is open source. I believe AOSP contains something very barebones. It has been a lot of years, am I incorrect?

The big difference here is the Message app on Android is just a normal app whereas imessage is bundled deep in the OS with tons of private apis

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#179

Earlier quoted context omitted.

Well dang I work in a research lab and I didn’t get an email. I’m just going to assume my research is so interesting that they sent the real badasses after me, somebody that Apple can’t catch. The truth is too ego-shattering.

Look to your left. Look to your right. Both of those people are working for a foreign government. At least one of them does not know it. Trust no one.

If this is sarcasm, I love it. If you're serious then I don't.

Re: Apple alerts users in 92 nations to mercenary spyware attacks

#180

Between the Metaverse, "mercenary spyware", AI war targeting, and death drones, I keep wondering who it is that read Neuromancer and thought; "What a rosy picture! How can we realize this stunning vision of a future-to-be?"

There will never be a shortage of people who read dystopia and think "That would be awful, I should oppress the entire world as it's rightful, righteous god king and make sure things go well (specifically how my extremely small perspective understands right and wrong)"

We see on this very board a huge segment of people who believe "tech" for "tech's sake" is a good thing, or that any "tech" is inherently an advancement of society, and that advancement === good

Post reply on HN